ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

UK police legal database breach exposes officer contact data, National Crime Agency investigating

The Police National Legal Database, an online legal reference platform used for more than 30 years by all 43 Home Office police forces in England and Wales as well as the British Transport Police, has confirmed a data breach that exposed contact information belonging to police officers, staff and other criminal justice professionals. The compromised data was published on the dark web, and the National Crime Agency is assisting with the investigation alongside private cybersecurity firms.


The database disclosed that names, organizations and work email addresses tied to police officers, staff, criminal justice professionals, government partners and customers were compromised and posted online. The organization stated there is no evidence that passwords or other security credentials were affected.


The breach also struck Ask the Police, a public question-and-answer service hosted on the same platform, exposing the names and email addresses of members of the public who had submitted inquiries through the site. That exposure creates two separate categories of risk: officers now face a heightened threat of phishing attempts built around their verified names, agencies and work emails, while members of the public who contacted police services have had that contact made visible on criminal forums.


The database’s most recent annual summary recorded 108,429 police registrations, offering a rough sense of scale, though the organization has not disclosed how many individuals were actually included in the breached dataset, nor has it released a timeline for when the intrusion began or a full account of how much data was taken.


The organization emphasized that it functions as a source of legal information and services for police forces and criminal justice bodies rather than a crime-recording system, and stated it does not hold confidential information related to victims, witnesses or offenders. It said all affected organizations were notified and given guidance, and that the incident was reported to the Information Commissioner’s Office.


The extortion group ExfilSquad listed the database as a victim on its leak site on July 26, claiming to have stolen roughly 1.9 gigabytes of data comprising approximately 135,000 records, split between 114,000 database subscribers and 21,000 Ask the Police users. The group also demanded a ransom to prevent the release of the remaining stolen material. The database has not attributed the intrusion to ExfilSquad or confirmed how the attackers gained access. ExfilSquad has also claimed a separate attack on American semiconductor company Analog Devices. The intrusion was reportedly detected on Sunday, July 26.


Cybersecurity firm VenariX examined samples tied to 11 of ExfilSquad’s 15 claimed victims and found structures consistent with Microsoft Dataverse in all of them, pointing to a possible pattern involving misconfigured Microsoft Power Pages portals, public-facing sites where overly permissive table access settings can leave data exposed to unauthenticated visitors.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543